
CVE-2026-18481 Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal session tokens and esc… https://www.cve.org/CVERecord?id=CVE-2026-18481
Post summary
The message announces a stored XSS vulnerability in AWS Ops Wheel that could allow authenticated users to hijack session tokens; no PoC, exploit, or patch is mentioned.

